CVE-2026-85637: jofpin trape Admin Endpoint sockets.py join_room missing authentication
A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function joinroom of the file core/sockets.py of the component Admin Endpoint. The manipulation results in missing authentication. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can target the affected Admin Endpoint without authentication. The vulnerability is in the join_room function in core/sockets.py.
Which versions are affected?
The reported affected versions are jofpin trape 1.0.0 and 2.0.0.
Is public exploit code available?
Yes. The exploit has been released publicly and may be used in attacks.
Is a fix available from the project?
The provided information does not identify a fix. It states that the project was notified through an issue report but had not responded.